GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,801
Erlang
36
GitHub Actions
29
Go
2,380
Maven
5,000+
npm
4,010
NuGet
720
pip
3,810
Pub
12
RubyGems
930
Rust
986
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,546 advisories
Filter by severity
GitHub Kanban MCP Server vulnerable to Command Injection
High
CVE-2025-53818
was published
for
@sunwood-ai-labs/github-kanban-mcp-server
(npm)
Jul 15, 2025
chromedriver Downloads Resources over HTTP
High
CVE-2016-10579
was published
for
chromedriver
(npm)
Feb 18, 2019
ag-grid Cross-Site Scripting vulnerability
High
GHSA-7p6w-x2gr-rrf8
was published
for
ag-grid
(npm)
Sep 2, 2020
@clerk/backend Performs Insufficient Verification of Data Authenticity
High
CVE-2025-53548
was published
for
@clerk/astro
(npm)
Jul 9, 2025
libwebp: OOB write in BuildHuffmanTable
High
CVE-2023-4863
was published
for
Pillow
(Go)
Sep 12, 2023
MCP Server Kubernetes vulnerable to command injection in several tools
High
CVE-2025-53355
was published
for
mcp-server-kubernetes
(npm)
Jul 8, 2025
Node.js Sandbox MCP Server vulnerability can lead to Sandbox Escape via Command Injection
High
CVE-2025-53372
was published
for
node-code-sandbox-mcp
(npm)
Jul 8, 2025
Next.JS vulnerability can lead to DoS via cache poisoning
High
CVE-2025-49826
was published
for
next
(npm)
Jul 3, 2025
react-native-keys insecurely stores encryption cipher and Base64 chunks
High
CVE-2025-45001
was published
for
react-native-keys
(npm)
Jun 9, 2025
@modelcontextprotocol/server-filesystem vulnerability allows for path validation bypass via colliding path prefix
High
CVE-2025-53110
was published
for
@modelcontextprotocol/server-filesystem
(npm)
Jul 1, 2025
@modelcontextprotocol/server-filesystem allows for path validation bypass via prefix matching and symlink handling
High
CVE-2025-53109
was published
for
@modelcontextprotocol/server-filesystem
(npm)
Jul 1, 2025
@cyanheads/git-mcp-server vulnerable to command injection in several tools
High
CVE-2025-53107
was published
for
@cyanheads/git-mcp-server
(npm)
Jun 30, 2025
tiny-secp256k1 allows for verify() bypass when running in bundled environment
High
CVE-2024-49365
was published
for
tiny-secp256k1
(npm)
Jun 30, 2025
tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environment
High
CVE-2024-49364
was published
for
tiny-secp256k1
(npm)
Jun 30, 2025
electron ASAR Integrity bypass by just modifying the content
High
CVE-2024-46992
was published
for
electron
(npm)
Jun 30, 2025
Claude Code Improper Authorization via websocket connections from arbitrary origins
High
CVE-2025-52882
was published
for
@anthropic-ai/claude-code
(npm)
Jun 23, 2025
Withdrawn Advisory: lunary-ai/lunary XSS in SAML metadata endpoint
High
CVE-2024-5478
was published
for
lunary
(npm)
Jun 6, 2024
•
withdrawn
Withdrawn Advisory: Lunary improper access control vulnerability
High
CVE-2024-6087
was published
for
lunary
(npm)
Sep 13, 2024
•
withdrawn
HaxCMS-PHP Command Injection Vulnerability
High
CVE-2025-49141
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jun 9, 2025
OpenNext for Cloudflare (opennextjs-cloudflare) has a SSRF vulnerability via /_next/image endpoint
High
CVE-2025-6087
was published
for
@opennextjs/cloudflare
(npm)
Jun 16, 2025
Regular Expression Denial of Service in papaparse
High
CVE-2020-36649
was published
for
papaparse
(npm)
Sep 4, 2020
Duplicate Advisory: PapaParse Inefficient Regular Expression Complexity vulnerability
High
GHSA-798h-g4j5-5537
was published
for
papaparse
(npm)
Jan 11, 2023
•
withdrawn
kangax html-minifier REDoS vulnerability
High
CVE-2022-37620
was published
for
html-minifier
(npm)
Oct 31, 2022
ProTip!
Advisories are also available from the
GraphQL API